Splunk Search

Are there field extractions available for IPlanet web access logs?

ndoshi
Splunk Employee
Splunk Employee

Here's the fields followed by a description:

Hostname or IP address of client

arrow.a.com. (In this case, the hostname is shown because the web server's setting for DNS lookups is enabled; if DNS lookups were disabled, the client's IP address would appear.

RFC 931 information

  • (RFC 931 identity not implemented)

Username

john (username entered by the client for authentication)

Date/time of request

29/Mar/1999:4:36:53 -0800

Request

GET /help

Protocol

HTTP/1.0

Status code

401

Bytes transferred

571

Tags (1)
0 Karma

kvaga
Explorer

Hello! I have more than five implementations of iplanet log files format string. Because a format of any web access log depends on the administrator who manages server.
Give me a few rows of your own log file and I'll give you exact string of field extraction

0 Karma

scruse
Path Finder

@kvaga i have a similar issue, how can i provide you with a sanitized sample so i dont repeat work already completed on this tech

0 Karma

ndoshi
Splunk Employee
Splunk Employee

Try these in props.conf

[iplanet]
EXTRACT-myfields=^(?.?[^\s])\s-\s(?.?[^\s])\s[(?.?)]\s\"(?\w+)\s(?.?[^\s])\s(?.*?)"\s(?\d+)\s(?\d+)\s(?\d+)

ndoshi
Splunk Employee
Splunk Employee

BTW, the other field is probably not needed. It's there in case you have some integer at the end of the event that is unaccounted for.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...